Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- apiVersion: rbac.authorization.k8s.io/v1
- kind: ClusterRole
- metadata:
- name: admin-safe
- rules:
- - apiGroups:
- - ""
- resources:
- - pods
- - pods/attach
- - pods/exec
- - pods/portforward
- - pods/proxy
- - configmaps
- - endpoints
- - persistentvolumeclaims
- - replicationcontrollers
- - replicationcontrollers/scale
- - secrets
- - serviceaccounts
- - services/proxy
- - bindings
- - events
- - limitranges
- - pods/log
- - pods/status
- - replicationcontrollers/status
- - resourcequotas
- - resourcequotas/status
- - serviceaccounts
- - rolebindings
- - roles
- - localresourceaccessreviews
- - localsubjectaccessreviews
- - subjectrulesreviews
- - podsecuritypolicyreviews
- - podsecuritypolicyselfsubjectreviews
- - podsecuritypolicysubjectreviews
- - rolebindingrestrictions
- - buildconfigs
- - buildconfigs/webhooks
- - builds
- - builds/log
- - buildconfigs/instantiate
- - buildconfigs/instantiatebinary
- - builds/clone
- - builds/details
- - deploymentconfigs
- - deploymentconfigs/scale
- - deploymentconfigrollbacks
- - deploymentconfigs/instantiate
- - deploymentconfigs/rollback
- - deploymentconfigs/log
- - deploymentconfigs/status
- - imagestreamimages
- - imagestreammappings
- - imagestreams
- - imagestreams/secrets
- - imagestreamtags
- - imagestreams/status
- - imagestreams/layers
- - imagestreamimports
- - appliedclusterresourcequotas
- - processedtemplates
- - templateconfigs
- - templateinstances
- - templates
- - buildlogs
- - resourcequotausages
- - resourceaccessreviews
- - subjectaccessreviews
- verbs:
- - '*'
- #namespaces,projects
- - apiGroups:
- - ""
- - project.openshift.io
- resources:
- - projects
- - namespaces/status
- - namespaces
- - services
- verbs:
- - create
- - get
- - list
- - watch
- - patch
- - update
- #daemonsets,deployments,statefulsets
- - apiGroups:
- - apps
- resources:
- - '*'
- verbs:
- - create
- - get
- - list
- - patch
- - update
- - watch
- verbs:
- - get
- - list
- - watch
- - apiGroups:
- - autoscaling
- - batch
- - extensions
- - policy
- - admissionregistration.k8s.io
- - apiextensions.k8s.io
- - apiregistration.k8s.io
- - apps.openshift.io
- - authentication.k8s.io
- - authorization.k8s.io
- - authorization.openshift.io
- - automationbroker.io
- - build.openshift.io
- - cassandra.rook.io
- - certificates.k8s.io
- - events.k8s.io
- - image.openshift.io
- - kafka.strimzi.io
- - keycloak.org
- - metrics.k8s.io
- - monitoring.coreos.com
- - network.openshift.io
- - networking.k8s.io
- - oauth.openshift.io
- - project.openshift.io
- - quota.openshift.io
- - rbac.authorization.k8s.io
- - resourcequotausages
- - route.openshift.io
- - scheduling.k8s.io
- - security.openshift.io
- - servicecatalog.k8s.io
- - settings.k8s.io
- - storage.k8s.io
- - template.openshift.io
- - user.openshift.io
- resources:
- - '*'
- verbs:
- - '*'
- - nonResourceURLs:
- - '*'
- verbs:
- - '*'
Advertisement
Add Comment
Please, Sign In to add comment